MRBAC/AR: an Information Flow Control Model to Prevent Both Intra- and Inter-Application Information Leakage

نویسنده

  • Shih-Chien Chou
چکیده

Preventing information leakage during program execution is essential for modern applications. This paper proposes a model to prevent information leakage for objectoriented systems, which is based on role-based access control (RBAC). It is named MRBAC/AR (modified RBAC for both intrAand inteR-application information flow control) because it is a modification of RBAC96. It offers the following features: (a) adapting to dynamic object state change, (b) adapting to dynamic role change, (c) avoiding Trojan horses, (d) detailing access control granularity to variables, (e) controlling method invocation through argument sensitivity, (f) allowing declassification, (g) allowing purpose-oriented method invocation, (h) precisely controlling write access, and (i) preventing both intraand inter-application information leakage. We evaluated MRBAC/AR through experiments. The evaluation result is also shown in this paper.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Third-order Decentralized Safe Consensus Protocol for Inter-connected Heterogeneous Vehicular Platoons

In this paper, the stability analysis and control design of heterogeneous traffic flow is considered. It is assumed that the traffic flow consists of infinite number of cooperative non-identical vehicular platoons. Two different networks are investigated in stability analysis of heterogeneous traffic flow: 1) inter-platoon network which deals with the communication topology of lead vehicles and...

متن کامل

CAMAC: a context-aware mandatory access control model

Mandatory access control models have traditionally been employed as a robust security mechanism in multilevel security environments such as military domains. In traditional mandatory models, the security classes associated with entities are context-insensitive. However, context-sensitivity of security classes and flexibility of access control mechanisms may be required especially in pervasive c...

متن کامل

A Mathematical Model for Cell Formation in CMS Using Sequence Data

Cell formation problem in Cellular Manufacturing System (CMS) design has derived the attention of researchers for more than three decades. However, use of sequence data for cell formation has been the least investigated area. Sequence data provides valuable information about the flow patterns of various jobs in a manufacturing system. This paper presents a new mathematical model to solve a cell...

متن کامل

Inter and Intra-Organizational Communication: The Facilitation Approaches to Strengthen and Sustain Rural Development Management in Portugal

The study describes and evaluates inter-organizational communication and relationships involving rural development management of community lands within specific perimetros florestais in Portugal. The research design is an exploratory research study approach that collected information with a mail questionnaire, interviews and information gleaned from community land association meetings and an in...

متن کامل

Managing the Intertwining among Users, Roles, Permissions, and User Relationships in an Information Flow Control Model

Information flow control prevents information leakage during the execution of an application. Many information flow control models are available and they offer useful features. In the past years, we identified that managing the intertwining among users, roles, permissions, and user relationships is essential. Since we cannot identify a model that manages the intertwining, we developed a new mod...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • J. Inf. Sci. Eng.

دوره 22  شماره 

صفحات  -

تاریخ انتشار 2006